By checking the box and proceeding, the individual acting on behalf of the organization identified during signup (the “Covered Entity” or “Practice”) (1) represents that they are authorized to bind the Covered Entity; (2) agrees that this Business Associate Agreement (“BAA” or "Agreement") is executed electronically between Covered Entity and SendVyte, LLC (“SendVyte”) (collectively, the “Parties”); and (3) agrees that this BAA is legally binding. The “Effective Date” is the date on which this acceptance is recorded. Covered Entity’s name, acceptance timestamp, BAA version, and this page URL may be stored by SendVyte as the execution record.
RECITALS
WHEREAS, Practice is a Covered Entity under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and maintains Protected Health Information ("PHI") as defined under 45 CFR § 160.103;
WHEREAS, SendVyte provides patient communication and practice operations services that may require access to, creation of, receipt of, maintenance of, or transmission of PHI on behalf of Practice, including an AI-assisted telephone receptionist; SMS appointment confirmations, reminders, and two-way patient messaging; review-request communications; patient-balance and accounts-receivable outreach; SVAlert Staff Chat, an expressly PHI-capable intra-practice staff coordination feature; referring-doctor analytics; and SummaryDocs, an AI-assisted clinical documentation feature that may use clinical notes, patient history, and other Practice-authorized PHI to assist Practice clinicians and staff in preparing draft S.O.A.P. notes and related clinical documentation for practitioner review (collectively, the "Services");
WHEREAS, SendVyte may access Practice data in read-only mode through a locally installed synchronization agent or an authorized data-integration provider to synchronize data reasonably necessary to provide the Services;
WHEREAS, the Parties desire to comply with HIPAA, the Health Information Technology for Economic and Clinical Health (HITECH) Act (collectively, the "HIPAA Rules") and their implementing regulations at 45 CFR Parts 160 and 164, permitting a covered entity to disclose PHI to a business associate, and permitting a business associate to create or receive PHI on its behalf, if the covered entity obtains satisfactory assurances that the business associate will appropriately safeguard the information; and
WHEREAS this BAA shall only apply to the extent that the Business Associate receives, maintains, transmits, uses, or discloses PHI to, from, or on behalf of the Covered Entity.
NOW, THEREFORE, in consideration of the mutual obligations under the terms of this BAA and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Parties agree as follows:
1. DEFINITIONS
1.1 HIPAA Terms. Capitalized terms used but not otherwise defined in this Agreement shall have the meanings assigned to them under the HIPAA Rules, including Breach, Designated Record Set, Disclosure, Individual, Minimum Necessary, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
1.2 Protected Health Information. "PHI" has the meaning set forth in 45 CFR § 160.103 and is limited to Protected Health Information which the Business Associate receives, maintains, transmits, uses, or discloses, to, from, or on behalf of the Covered Entity and includes, to the extent applicable, information contained in telephone-call records, recordings, transcripts and summaries; patient text-message threads; SVAlert Staff Chat and other PHI-approved intra-practice staff coordination messages; and clinical notes, patient histories, draft S.O.A.P. notes, and related clinical documentation processed through SummaryDocs.
1.3 Electronic Protected Health Information. "ePHI" means PHI transmitted by or maintained in electronic media.
2. OBLIGATIONS OF BUSINESS ASSOCIATE
2.1 Permitted Uses and Disclosures. SendVyte shall use or disclose PHI only as permitted or required by this Agreement or the applicable services agreement, or as Required By Law. SendVyte may use PHI as reasonably necessary to provide and administer the Services to the Covered Entity, provided that any such use or disclosure is consistent with the HIPAA Rules.
2.2 Safeguards. SendVyte shall implement and maintain appropriate administrative, physical, and technical safeguards designed to prevent use or disclosure of PHI other than as provided for by this Agreement. With respect to ePHI, SendVyte shall comply with the applicable requirements of Subpart C of 45 CFR Part 164.
2.3 Minimum Necessary. To the extent required by the HIPAA Rules, SendVyte shall limit its uses, disclosures, and requests for PHI to the Minimum Necessary to accomplish the intended purpose.
2.4 Security Practices. SendVyte shall maintain safeguards appropriate to the nature of the Services and the PHI handled. Such safeguards may include encryption in transit and at rest, access controls, authentication and session controls, logical tenant segregation, restricted workforce access, security monitoring, and documented retention controls. Specific technical implementations may evolve over time, provided that SendVyte continues to satisfy its obligations under the HIPAA Rules and this Agreement.
2.4A PHI-Capable Staff Chat. SendVyte expressly designates SVAlert Staff Chat as functionality approved for authorized Practice workforce communications that may contain PHI. Other SVAlert room-alert, status-board, acknowledgement, or workflow functionality is not approved for entry of PHI unless SendVyte expressly designates that functionality as PHI-capable. Staff Chat is separate from PMS synchronization and does not itself retrieve PHI from the Practice PMS. SendVyte shall apply safeguards and retention controls appropriate to Staff Chat as a PHI-capable feature.
2.5 Reporting of Unauthorized Uses, Disclosures, and Security Incidents. SendVyte shall report to Practice any use or disclosure of PHI not permitted by this Agreement of which SendVyte becomes aware and any Security Incident of which SendVyte becomes aware, as required by the HIPAA Rules. The Parties acknowledge that routine unsuccessful attempts to gain unauthorized access to systems containing ePHI, including unsuccessful log-in attempts, pings, port scans, denial-of-service attempts, and other attacks that do not result in unauthorized access, use, disclosure, modification, or destruction of ePHI, need not be individually reported unless otherwise required by law.
2.6 Subcontractors. In accordance with 45 CFR §§ 164.502(e)(1)(ii) and 164.308(b)(2), as applicable, SendVyte shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of SendVyte agrees in writing to restrictions, conditions, and requirements that are at least as protective of PHI as those applicable to SendVyte under this Agreement. SendVyte may maintain a current subprocessor or subcontractor list outside this Agreement and may update that list as its service providers change.
2.7 Access. To the extent PHI maintained by SendVyte is part of a Designated Record Set and is not otherwise available to Practice, SendVyte shall make such PHI available to Practice as reasonably necessary for Practice to satisfy its obligations under 45 CFR § 164.524. Unless a shorter period is required by applicable law or agreed by the Parties, SendVyte shall respond to a written request from Practice within fifteen (15) business days.
2.8 Amendment. To the extent PHI maintained by SendVyte is part of a Designated Record Set, SendVyte shall make amendments to PHI as directed by Practice, or take other measures as reasonably necessary for Practice to satisfy its obligations under 45 CFR § 164.526. Unless a shorter period is required by applicable law or agreed by the Parties, SendVyte shall respond within fifteen (15) business days.
2.9 Accounting of Disclosures. SendVyte shall maintain and make available information required for Practice to provide an accounting of disclosures as necessary to satisfy Practice's obligations under 45 CFR § 164.528.
2.10 Performance of Covered Entity Obligations. To the extent SendVyte is expressly delegated responsibility to carry out one or more of Practice's obligations under Subpart E of 45 CFR Part 164, SendVyte shall comply with the requirements of Subpart E applicable to Practice in the performance of such obligation.
2.11 Government Access. SendVyte shall make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received on behalf of, Practice available to the Secretary for purposes of determining compliance with the HIPAA Rules.
2.12 AI Processing. To the extent SendVyte uses artificial-intelligence service providers to process PHI, SendVyte shall use service configurations and contractual arrangements that SendVyte has determined are appropriate for such PHI processing under the HIPAA Rules. Unless expressly authorized in writing by Practice and permitted by applicable law, SendVyte shall not use Practice PHI to train generalized artificial-intelligence models.
3. OBLIGATIONS OF COVERED ENTITY
3.1 Notice of Privacy Practices. Practice shall notify SendVyte of any limitation in Practice's Notice of Privacy Practices, to the extent such limitation may affect SendVyte's permitted use or disclosure of PHI.
3.2 Restrictions and Revocations. Practice shall notify SendVyte of any restriction on the use or disclosure of PHI that Practice has agreed to or is required to honor under 45 CFR § 164.522, and of any changes in, or revocation of, an Individual's permission to use or disclose PHI, to the extent such matters may affect SendVyte.
3.3 Permissible Instructions. Practice shall not request, direct, or require SendVyte to use or disclose PHI in a manner that would violate the HIPAA Rules if performed by Practice, except to the extent a Business Associate is expressly permitted by the HIPAA Rules to make such use or disclosure.
3.4 Patient Communications and SMS. Practice is responsible for determining and documenting the legal basis, permissions, and consents necessary for its patient communications and for maintaining accurate contact-preference, opt-out, and Do Not Contact records. SendVyte shall implement supported opt-out controls in accordance with the Services and applicable law.
3.5 Call Recording, Transcription, and AI Disclosures. Practice is responsible for determining whether call recording, transcription, or AI-assisted call handling will be enabled for Practice and for obtaining and maintaining any caller notices or consents required by applicable law for Practice's use of those features. SendVyte may provide configurable disclosure functionality or sample language, but does not provide legal advice regarding the sufficiency of Practice's disclosures.
3.6 Clinical Documentation and SummaryDocs. SummaryDocs is an assistive drafting tool and does not independently diagnose, treat, or make clinical decisions. Practice is responsible for determining whether SummaryDocs is appropriate for its workflows and for ensuring that a qualified Practice clinician reviews, verifies, edits as appropriate, and approves any AI-assisted clinical documentation before it is relied upon for patient care or incorporated into the medical or dental record.
4. SCOPE OF PHI ACCESSED, CREATED, OR RECEIVED
4.1 PMS-Synchronized Data. Depending on the Services enabled and the Practice's PMS or data-integration configuration, SendVyte may synchronize categories of data reasonably necessary to provide the Services, which may include:
Patient names, phone numbers, email addresses, and dates of birth;
Appointment dates, times, types, providers, operatory assignments, and appointment status;
Doctor and referring-doctor information;
Insurance carrier names, where used by an enabled Service;
Communication-consent status and Do Not Contact flags; and
Outstanding patient-balance amounts or other limited financial data reasonably necessary for an enabled patient-balance or payment-communication Service; and
Clinical notes, patient history, prior clinical documentation, and related chart information reasonably necessary for SummaryDocs or another Practice-enabled clinical-documentation Service.
4.2 Communications Data. In the course of providing the Services, SendVyte may create, receive, maintain, or transmit:
Telephone-call records, caller-provided information, structured call summaries, callback numbers, and, where enabled, call recordings and transcripts;
Patient text-message threads and delivery records;
SVAlert Staff Chat messages and other intra-practice staff coordination messages transmitted through functionality expressly designated by SendVyte as PHI-capable, subject to the security and retention controls applicable to that feature; and
Review-request, payment-link, reminder, and related delivery records.
4.3 Data Not Intentionally Retrieved from the PMS. Except where expressly required by an enabled Service, SendVyte is not configured through its current PMS synchronization functionality to retrieve radiographic or diagnostic images or scans, Social Security numbers, government-issued identifiers, or detailed billing-ledger transaction records. SummaryDocs is expressly designed to process Practice-authorized clinical notes, patient history, prior clinical documentation, and related PHI reasonably necessary to assist Practice clinicians and staff in preparing draft S.O.A.P. notes and related clinical documentation. Patients, callers, Practice personnel, or other users may also independently provide clinical information or other PHI through calls, messages, forms, or other communications handled by the Services.
4.4 Ownership. As between the Parties, Practice retains all right, title, and interest in and to Practice PHI. Nothing in this Agreement transfers ownership of Practice PHI to SendVyte.
5. TERM AND TERMINATION
5.1 Term. This Agreement shall become effective as of the Effective Date and remain in effect for so long as SendVyte creates, receives, maintains, or transmits PHI on behalf of Practice, unless terminated earlier in accordance with this Agreement.
5.2 Termination for Cause. Either Party may terminate this BAA if the other Party materially breaches this BAA and the breaching Party does not cure the breach or end the violation within a reasonable timeframe. In the event of a breach for which a cure is not possible, this BAA may be terminated immediately upon notice by the non-breaching Party.
5.3 Return or Destruction of PHI. Upon termination of the applicable Services, SendVyte shall, if feasible, return or destroy PHI received from Practice or created or received on behalf of Practice in accordance with SendVyte's applicable post-termination retention and deletion process described in Section 5.4 where returning or destroying PHI is commercially reasonable and technically feasible. If feasible to do so, SendVyte shall further return or destroy all PHI in possession of SendVyte’s subcontractors. The PHI shall be returned in a format that protects the security, integrity, and availability of the PHI and other data. Such format and method of delivery shall be mutually agreed upon if it is not otherwise addressed in the underlying Agreement.
If return or destruction is not feasible, SendVyte shall extend any and all protections, limitations, and restrictions contained in this Agreement to SendVyte’s use and/or disclosure of any PHI retained after the expiration or termination of this Agreement and shall limit any further uses and/or disclosures solely to the purposes that make return or destruction of the PHI infeasible for so long as SendVyte maintains such PHI.
5.4 Post-Termination Retention and Deletion. Unless otherwise required by law or agreed in writing, Practice data may be retained for up to ninety (90) days following cancellation of the applicable Services to permit export, transition, backup expiration, and orderly deletion, after which it will be deleted or rendered inaccessible in accordance with SendVyte's documented deletion processes. Data classes subject to shorter product-retention schedules will continue to be purged on their ordinary schedules. Practice may request earlier deletion in writing, and SendVyte shall use commercially reasonable efforts to complete such deletion within thirty (30) days, subject to legal holds, backup-cycle limitations, security requirements, and other circumstances in which immediate deletion is not reasonably feasible.
6. BREACH NOTIFICATION
6.1 Notification. SendVyte shall notify Practice of any Breach of Unsecured PHI as required by 45 CFR § 164.410 without unreasonable delay and in no case later than thirty (30) calendar days after discovery of the Breach.
6.2 Content of Notification. To the extent available, SendVyte's notification shall include the information required by 45 CFR § 164.410(c), including identification of affected Individuals, a brief description of what happened, the date of the Breach and date of discovery if known, the types of Unsecured PHI involved, and other information reasonably available to assist Practice in meeting its notification obligations.
6.3 Cooperation and Allocation of Costs. SendVyte shall reasonably cooperate with Practice in investigating and responding to a Breach involving PHI handled by SendVyte. The allocation of investigation, notification, remediation, indemnification, and related costs between the Parties shall be governed by the applicable services agreement, except to the extent otherwise required by applicable law.
7. GENERAL PROVISIONS
7.1 Regulatory References. A reference in this Agreement to a section of the HIPAA Rules means the section as in effect or as amended from time to time.
7.2 Amendment to Maintain Compliance. The Parties shall amend this Agreement as reasonably necessary to comply with changes in applicable law. Other amendments must be in writing and signed by authorized representatives of both Parties.
7.3 Survival. SendVyte's obligations with respect to PHI retained after termination shall survive for so long as SendVyte maintains such PHI.
7.4 Governing Law. This Agreement shall be governed by the laws of the State of Georgia, except to the extent preempted by applicable federal law.
7.5 Order of Precedence. This Agreement supplements the Parties' applicable services agreement. In the event of a conflict concerning the use or disclosure of PHI or compliance with the HIPAA Rules, this Agreement controls. Commercial terms, including limitations of liability and indemnification, are governed by the applicable services agreement unless this Agreement expressly states otherwise.
7.6 Severability. If any provision of this Agreement is held invalid or unenforceable, the remaining provisions shall remain in full force and effect.
7.7 No Third-Party Beneficiaries. This Agreement is intended solely for the benefit of the Parties and does not create contractual rights or remedies in any third party; provided, however, that nothing in this Section limits any rights or remedies available under applicable law.
7.8 Liability and Indemnification. Except to the extent otherwise required by applicable law, the Parties' indemnification obligations, exclusions of damages, limitations of liability, and related remedies arising out of or relating to this Agreement shall be governed by the applicable services agreement.